首页> 外文期刊>Government information quarterly >Beyond the Castle Model of cyber-risk and cyber-security
【24h】

Beyond the Castle Model of cyber-risk and cyber-security

机译:超越网络风险和网络安全的城堡模型

获取原文
获取原文并翻译 | 示例
           

摘要

The predominant metaphor for secure computing today is modeled on ever higher, ever better layers of walls. This article explains why that approach is as outmoded for cyber security today as it became for physical security centuries ago. Three forces are undermining the Castle Model as a practical security solution. First, organizations themselves tear down their walls and make their gateways more porous because it pays off in terms of better agility and responsiveness - they can do more, faster and better. Second, technological developments increasingly destroy walls from the outside as computation becomes cheaper for attackers, and the implementation of cyberwalls and gateways becomes more complex, and so contains more vulnerabilities to be exploited by the clever and unscrupulous. Third, changes in the way humans and technology interact, exemplified (but not limited to) the Millennial generation, blur and dissolve the concepts of inside and outside, so that distinctions become invisible, or even unwanted, and boundaries become annoyances to be circumvented. A new approach to cyber security is needed: Organizations and individuals need to get used to operating in compromised environments. The article's conclusion hints at more nuanced forms of computation in environments that must be assumed to be potentially compromised. Crown Copyright (C) 2016 Published by Elsevier Inc. All rights reserved.
机译:如今,安全计算的主要隐喻是建立在越来越高,越来越好的墙壁上的。本文解释了为什么这种方法在当今的网络安全中已经不如几个世纪前的物理安全过时了。三股力量正在破坏作为实际安全解决方案的城堡模型。首先,组织自己拆除墙壁并使其网关更加多孔,因为它在更好的敏捷性和响应能力方面得到了回报-他们可以做更多,更快和更好。其次,随着计算技术对攻击者的价格越来越便宜,技术的发展越来越多地从外部破坏了城墙,而网络墙和网关的实施也变得更加复杂,因此包含了更多的漏洞,这些漏洞将被聪明和不道德的人利用。第三,人类与技术互动方式的变化,例如(但不限于)千禧一代,模糊并消解了内在和外在的概念,从而使区分变得无形甚至是不必要的,而边界则成为规避烦恼的烦恼。需要一种新的网络安全方法:组织和个人需要习惯于在受到威胁的环境中进行操作。本文的结论暗示了在必须假定可能受到危害的环境中,计算的细微差别形式。 Crown版权所有(C)2016,由Elsevier Inc.保留。保留所有权利。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号